Cloud Security Engineer
Indexed description
Due to the nature of the role's work with FedRamp, US Citizenship is required
Picture Yourself At Pega
You'll be a part owner of Pega's FedRamp/cloud environment, responsible for both day-to-day operational security and sprint-based feature delivery. You'll work alongside peers delivering AI-driven remediation pipelines, identity automation, and cloud security tooling, and are expected to contribute to that innovation work alongside your responsibilities.
This is an engineering role. You write code, build automation, operate regulated infrastructure, and ship features, not just process tickets.
What You'll Do At Pega
Access Governance & Identity Operations (30%)
- Own Okta administration for PCFG and Commercial environments: MFA resets, account provisioning, Okta Verify troubleshooting, policy enforcement
- Manage IAM roles, permission boundaries, deployment entitlements, and access reviews across PCFG accounts (CloudOps, Jenkins, deployment pipelines)
- Build and maintain entitlement automation workflows for joiner/mover/leaver processes
- Support SailPoint quarterly certifications and access request workflows; contribute to AI-assisted certification automation
- Operate Nessus/Tenable and Netsparker scanning across PCFG RnD and PCFG Prod
- Respond to audit scan requests (UKCE, SOC, FedRAMP assessors) with findings and evidence
- Track and ensure zero high-severity findings outstanding beyond 30 days
- Execute FedRAMP Control Plane patching cycle every sprint — mandatory compliance obligation, non-negotiable
- Execute PCFG RnD OS automated patching and validate Commercial environment patches (SailPoint, PingCastle)
- Maintain patch compliance metrics; escalate blockers before sprint close
- Contribute to SSM Patch Manager automation to reduce manual patching overhead over time
- Build infrastructure automation: Control Tower account provisioning, PCFG account lifecycle, CloudFormation role deployment
- Develop SSM Patch Manager alerting and role infrastructure
- Respond to ad-hoc infrastructure requests: IAM policy changes, Global Accelerator, Lambda roles, Bedrock model enablement
- Contribute to team-wide AI-driven remediation features — SOAR response actions, AWS Config automation, and AI intake tooling
- 3+ years in cloud security engineering or a closely adjacent role; hands-on with AWS (IAM, CloudFormation, SSM, Inspector, Config, GuardDuty)
- Experience operating in a FedRAMP or similarly regulated environment, you understand what compliance-driven delivery looks like
- Proficient with identity platforms: Okta administration, SailPoint or equivalent IGA tooling
- Comfortable writing automation: Python, shell, CloudFormation/Terraform, you don't wait for someone else to build the script
- Familiar with vulnerability scanning tools (Nessus/Tenable, Netsparker, or AWS Inspector)
- You operate well in a team that splits time between BAU obligations and feature delivery, context-switching is part of the job
- Exposure to SOAR platforms (Chronicle SecOps, Siemplify, or similar) is a plus
- Experience with GitHub-based CI/CD pipelines,you're comfortable with PR-gated workflows, GitHub Actions, and treating infrastructure and security content as code that gets reviewed before it ships
- You use AI tools (Copilot, ChatGPT, or similar) as part of how you build, scaffolding automation, generating test cases, accelerating repetitive engineering work and you know how to validate what comes out
- Gartner Analyst acclaimed technology leadership across our categories of products
- Continuous learning and development opportunities
- An innovative, inclusive, agile, flexible, and fun work environment
- Competitive global benefits program inclusive of pay + bonus incentive, employee equity in the company ()
The final compensation will be determined during the offer process based on the candidate's education, experience, skills, and qualifications, as well as market conditions and may vary from the posted range. We will share an information on benefits, bonus/commission, and other pay components for this role at the relevant recruitment stage.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search